Privacy Policy

Last updated: August 5, 2026

This Privacy Policy explains how eLawPlatform collects, uses, and safeguards personal data when you use our website and platform. To act on your rights instead of reading about them, go to Your Privacy Choices.

The three commitments behind everything below

We do not sell personal data. We do not share it for advertising. We do not use customer content to train AI models. Everything else is detail.

To exercise a right, see Your Privacy Choices.

1. Two roles, two sets of rules

For your account — your name, email, role, login and billing records — we are the controller: we decide how that data is handled, and this policy governs it.

For the content inside a firm's workspace — documents, prompts, conversations, and the personal data of clients and counterparties within them — the firm is the controller and we are the processor, acting on the firm's instructions under our Data Processing Agreement. If you are a client of a firm that uses eLawPlatform, your requests go to that firm; we will forward anything sent to us.

2. Information we collect

Account information. Name, email address, firm name, role, and authentication credentials. Passwords are stored as bcrypt hashes; we never see your plaintext password.

Customer content. Documents you upload, prompts you submit, conversations with the AI Assistant, agent runs, and research queries.

Billing information. Plan, subscription status, invoice history, and payment method tokens held by Stripe. We do not store full card numbers.

Usage information. IP address, browser and device type, pages viewed, product events, and timestamps — used to operate, secure, debug, and improve the Service.

Communications. Support messages, contact-form submissions, and their attachments.

Cookies. See the Cookie Policy for the full list. We set no advertising or cross-site tracking cookies.

We collect this from you directly, automatically as you use the Service, and — for a Member joining an existing workspace — from the administrator who invited them.

3. How we use information

  • Provide, maintain, and secure the Service
  • Authenticate users and manage firm workspaces
  • Process payments and manage subscriptions
  • Generate AI responses through our model providers
  • Send transactional messages about your account, billing, and security
  • Provide support and respond to enquiries
  • Detect, investigate, and prevent abuse, fraud, and security incidents
  • Produce aggregated, de-identified statistics that do not identify anyone
  • Comply with legal obligations and enforce our Terms

We do not use personal data for advertising, and we do not make decisions about individuals by automated means that produce legal or similarly significant effects — see AI Transparency.

4. AI training

We do not use customer content to train foundation models. Prompts and document context are sent to third-party model providers under terms that prohibit them from training on your data or sharing it with other customers. Details, including which providers run where, are on the AI Transparency & Disclosures page.

5. Legal bases (GDPR / UK GDPR)

For users in the EEA, UK, and Switzerland we rely on: performance of a contract (providing the Service); legitimate interests (securing the Service, preventing abuse, improving the product — balanced against your rights); compliance with legal obligations (tax, accounting, responding to lawful process); and consent, where required, for non-essential cookies. You may withdraw consent at any time without affecting processing already carried out.

6. Sharing & disclosure

We disclose personal data only to:

  • Subprocessors that help us run the Service, each bound by data-protection terms no less protective than our DPA. The current list is on the Subprocessors page.
  • Other Members of your workspace, limited to what their role permits.
  • Professional advisers — auditors, lawyers, accountants — under duties of confidence.
  • Authorities, where compelled by valid legal process, on the terms set out in our Law Enforcement Request Guidelines — including our default of notifying you first.
  • An acquirer, in a merger, acquisition, financing, or sale of assets, subject to equivalent protections and with notice to you before your data becomes subject to a different policy.

We do not sell personal data and we do not share it for cross-context behavioural advertising or targeted advertising.

7. Data retention

We keep personal data only as long as we need it for the purpose it was collected, or as long as the law requires.

DataRetentionNotes
Customer content (documents, prompts, conversations, agent runs)Until you delete it; 30 days after the account closesPurged from production; backups expire on rotation
Account records (name, email, role, firm)Life of the account + 30 daysDeleted or irreversibly anonymised
Billing and invoice records7 yearsRetained to meet tax, accounting, and audit obligations
Security and audit logs12 months (longer where an investigation is open)Retained to detect and investigate abuse
Application and error logs30 daysRolling deletion
BackupsUp to 90 daysEncrypted, restored only for disaster recovery
Data-subject request records24 monthsKept to evidence that we handled the request

Deletion from production is not instantaneous in backups: an encrypted backup taken before a deletion still contains the record until that backup expires. Backups are never used to repopulate deleted data.

8. Security

We use administrative, technical, and physical safeguards including TLS 1.2+ in transit, AES-256 at rest, role-based access control, per-workspace isolation, audit logging, and least-privilege access for staff. The detail is on the Security page. No system is perfectly secure; we do not claim otherwise.

If something goes wrong

Where a breach affects your personal data we notify you without undue delay and, where we act as processor, within the timelines in the DPA — normally within 72 hours of becoming aware. Notice describes what happened, what data was involved, what we have done, and what you should do.

9. International transfers

We are established in the United States and our primary infrastructure is in the United States. Using the Service from elsewhere means your data is transferred to and processed in the US.

For transfers out of the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses (Module Two, controller to processor) together with the UK International Data Transfer Addendum, incorporated by our DPA, and we assess the destination's laws and apply supplementary measures where needed. A copy of the clauses is available on request from privacy@elawplatform.com.

10. Your rights

Depending on where you live you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, to opt out of sale, sharing, targeted advertising, and profiling, and to appeal a refusal. These rights arise under the EU and UK GDPR, the California Consumer Privacy Act as amended, the Florida Digital Bill of Rights, and the privacy acts of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states.

We extend these rights to every user, everywhere. How to use them — including the self-service export and erasure controls in Settings → Profile, verification, timelines, authorised agents, and the appeal route — is set out in Your Privacy Choices.

Exercising a right never results in worse service, a higher price, or a reduced feature set.

11. Children

The Service is not directed to anyone under 18 and we do not knowingly collect personal data from children. If you believe a child has given us personal data, write to privacy@elawplatform.com and we will delete it.

12. Changes to this policy

We may update this policy. Material changes are notified through the Service or by email at least 30 days before they take effect, and the effective date at the top of this page is updated. Previous versions are available on request.

13. Contact

Privacy questions, requests, and complaints go to privacy@elawplatform.com. We respond to every enquiry, and you always have the right to complain to your supervisory authority or state Attorney General.